Coldcard Hack Sparks $620M Rush into Spot Bitcoin ETFs
A recent firmware vulnerability in older Coldcard hardware wallets compromised seed phrase generation, allowing attackers to reconstruct private keys. This flaw affected over 5,200 wallet addresses between July 30 and early August 2026.
The Coinkite CEO advised users with affected devices to transfer their funds immediately after the issue was disclosed on July 31. Approximately 1,367 BTC were drained from these addresses, translating to around $89 million in losses at the time of the breach.
Newer Coldcard models experienced a lesser degree of exposure due to the partial nature of the entropy reduction. The broader market reacted mildly to the news, with Bitcoin's price dipping by only 3% before stabilizing near prior levels.
The more significant response came from spot Bitcoin ETFs, which recorded $620 million in daily inflows across various tickers during this period. This influx was not limited to a single fund and suggests potential investors seeking safer alternatives amid the risk of hardware vulnerabilities.